Collective Learning AI Pty Ltd
Trust & security
Last updated: 8 Jul 2026
This page describes how we protect your data, where it is processed, who we rely on, and where our compliance program stands today. We state only what is true and in place; where something is in progress we say so. For a deeper review, organisational customers can request our security questionnaire responses, data-processing agreement, and data-flow map under a non-disclosure agreement using the contact below.
Where your data lives
Collective Learning AI is hosted in Australia on infrastructure we own and operate. Your account, learning, and assessment data are stored on that Australian infrastructure, and encrypted backups are kept in Australia.
Conversational AI processing currently uses Google Gemini (a disclosed subprocessor), which may process submitted content in the United States. An on-premises AI migration is in progress that will bring this processing onto our own Australian infrastructure; we will update this page and our subprocessor register when it completes.
Security posture
Each item below reflects a control that is implemented and evidenced today, unless marked otherwise.
- In placeAdministrative MFAAccess to the application’s administrative surfaces requires a time-based one-time-password second factor, enforced in production. Infrastructure administration is key-only on a separated management network.
- In placeEncryption in transitTLS 1.2+ terminates on infrastructure we control, with HSTS and a strict content-security policy.
- In placeAccess controlKey-only administrative access on a separated management network; scoped roles; server-side session revocation; per-organisation, fail-closed authorisation on organisational data.
- In placeBackups & disaster recoveryPoint-in-time recovery with an approximately one-minute recovery-point objective, plus regular full backups, encrypted and stored offsite in Australia, with automated weekly restore rehearsals.
- In placeLogging & monitoringApplication audit logging and privileged-data-access audit trails, alerting on privilege-escalation events, and a logging pipeline governed by a no-personal-data-in-logs rule enforced in continuous integration.
- In placeSecure developmentProtected release branch with four required checks including an automated security review, secret scanning on every change, and health-gated deployment with automatic rollback.
- In placeData minimisation, retention & deletionAutomated retention expiry, personal-information sanitisation on document extraction, and a self-service account-deletion workflow with confirmation records.
- In progressEnterprise SSO & SCIMSingle sign-on (OpenID Connect, then SAML) and automated provisioning are in active delivery — treat as forthcoming until this page states otherwise.
Subprocessors
We keep the number of third parties that can process personal data deliberately small. The current list:
| Subprocessor | Purpose | Location |
|---|---|---|
| Google (Gemini API) | Conversational AI processing — migration on-premises in progress | United States |
| Google (OAuth) | Optional “sign in with Google” authentication | United States / global |
| Resend | Transactional and notification email | United States |
| Amazon Web Services (S3) | Encrypted backup storage (ciphertext only; we hold the keys) | Australia (Sydney) |
We do not use third-party web-analytics, advertising, or cross-site tracking services. Course video and the conversational avatar are self-hosted. Organisational customers receive the full, versioned register and change notice under their agreement.
Certifications & testing
- In progressISO 27001An ISO 27001-aligned information-security program is underway (scope, control-evidence mapping, and gap register in place). We are not yet certified and do not represent ourselves as certified.
- In progressIndependent penetration testA test-readiness pack (scope, production-mirror target, remediation protocol) is prepared; an independent engagement is being arranged. We will publish the completion here.
- PlannedSOC 2Planned for when US-market demand warrants it; roughly 80% of the evidence overlaps with the ISO program.
Accessibility
We design and build against the Web Content Accessibility Guidelines (WCAG) 2.2 level AA and treat accessibility as part of our definition of done. We have not yet completed an independent conformance audit; our current approach and how to report an issue are on our accessibility statement.
Privacy
We handle personal information under the Australian Privacy Principles (Privacy Act 1988 (Cth)) and the Notifiable Data Breaches scheme. Our privacy policy covers what we collect, how we use it, cross-border processing, workplace deployments, and the assistive, human-in-the-loop nature of our assessments (they are not automated decision-making). See also our cookie policy.
Reporting a vulnerability
We welcome good-faith security research. If you believe you have found a vulnerability, email contact@collectivelearning.ai with the subject line “Security disclosure” and enough detail to reproduce the issue. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, and do not access, modify, or delete data that is not your own. We will acknowledge your report, keep you informed of our progress, and will not pursue good-faith research conducted within these guidelines.
Questions & assessment support
Security or procurement teams evaluating Collective Learning can request our security questionnaire responses, data-processing agreement, subprocessor register, and data-flow map under a non-disclosure agreement. Contact contact@collectivelearning.ai.
